Colorado AI Act

The Colorado AI Act is a U.S. state law regulating high-risk AI systems, built around a duty to protect consumers from algorithmic discrimination. It sits at the front of a state-by-state patchwork now spreading across the country, and it puts obligations on both the developers and the deployers of consequential AI.

In Depth

Enacted as Colorado SB 24-205 and signed in 2024, the Act targets high-risk AI systems, meaning those that make, or are a substantial factor in making, a consequential decision affecting a consumer in areas like employment, lending, housing, education, healthcare, insurance, and legal services. For those systems, the law imposes a duty of reasonable care to protect consumers against algorithmic discrimination, and it splits responsibilities between the developer who builds the system and the deployer who puts it to use.

In practice the duty translates into documentation, disclosure, and risk-management expectations: telling consumers when a high-risk system is used in a decision about them, maintaining impact assessments, and being able to show the steps taken to identify and reduce discriminatory outcomes. The reasonable-care framing matters because it's a negligence-style standard, so what counts as compliant turns on whether you took the kinds of precautions a careful operator would. That makes evidence of governance, not just good intentions, the thing that protects you.

The Act takes effect in 2026. What matters more is what it signals: with no single federal AI law, states are legislating one at a time, and Colorado is the template others are drafting against. A vendor selling into multiple states is heading toward a quilt of overlapping, non-identical obligations rather than one rule to satisfy.

What It Looks Like

A vendor's AI agent helps a lender decide which applicants to approve. Because a lending decision is a consequential decision under the Act, the agent is a high-risk system, and both the vendor (developer) and the lender (deployer) pick up duties. The lender has to disclose the AI's role to applicants and maintain its impact assessment; the vendor has to supply the documentation that makes that possible and show it exercised reasonable care against discriminatory outcomes. A single rejected applicant's complaint can put both parties' reasonable-care story to the test.

Why It Matters For AI Vendors

The deployer obligations mean your enterprise customers are now regulated parties when they use your agent, and they will push their obligations upstream to you in the contract. They need your documentation and your testing records to meet their own duty of care. A vendor who can't supply them becomes the weak link that stalls the deal.

The patchwork makes it worse. Colorado is first, not last. A vendor selling nationally can't build to one statute and forget it; the obligations vary by state and arrive on different timelines. Tracking that by hand, across a growing list of laws, is exactly the kind of work that slips until a complaint forces it.

Common Questions

What matters is whether your high-risk system is used to make consequential decisions about Colorado consumers, not where your company sits. Selling into the state can bring you within scope.
If you build and supply the AI system, you carry developer duties; your enterprise customer using it typically carries deployer duties. Many obligations are split, which is why customers push documentation requirements back to vendors.
They share a risk-tiered, anti-discrimination spirit but are separate laws with different scopes and duties. See EU AI Act. Reggie maps both against your agent.
← PreviousClaims-Made Policy Next →Commercial General Liability (CGL)

See where your AI agents stand.

Get an Agent Trust Score, map your liability exposure, and find out what it takes to make your AI agents insurable.